CVE Notify
19.5K subscribers
4 photos
232K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2023-25606
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4  all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

πŸŽ–@cveNotify
🚨 CVE-2023-35317
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-35313
Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-35310
Windows DNS Server Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-35318
Remote Procedure Call Runtime Denial of Service Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-34089
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing. The problem was patched in version 0.27.3 and 0.26.6.


πŸŽ–@cveNotify
🚨 CVE-2023-33170
ASP.NET and Visual Studio Security Feature Bypass Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-33150
Microsoft Office Security Feature Bypass Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-33127
.NET and Visual Studio Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-32056
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-32046
Windows MSHTML Platform Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-32039
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-21526
Windows Netlogon Information Disclosure Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-32050
Windows Installer Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-33165
Microsoft SharePoint Server Security Feature Bypass Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-29347
Windows Admin Center Spoofing Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2023-30607
icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no known workarounds.

πŸŽ–@cveNotify
🚨 CVE-2023-35974
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

πŸŽ–@cveNotify
🚨 CVE-2023-31248
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace

πŸŽ–@cveNotify
🚨 CVE-2023-34834
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.

πŸŽ–@cveNotify